Security Advisory – April, 2024: Neat Statement on the XZ Utils Vulnerability

Advisory ID: NEAT-SA-2024-04-12
Publication date: April 12, 2024
Last updated: April 12, 2024

Severity: Critical — CVSS v3.1 Base Score: 10.0 (severity of the underlying XZ Utils vulnerability; Neat determined it does not affect Neat products)

CVSS vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (Red Hat scoring, via NVD)
CVE ID: CVE-2024-3094

Summary

Malicious code was deliberately inserted into XZ Utils, a widely used open-source compression library included in many Linux distributions. The backdoor targets the SSH daemon authentication process and could allow a remote attacker to execute arbitrary code on an affected machine. It affects XZ Utils versions 5.6.0 and 5.6.1 when installed from a complete package download.

Affected Products

None. Neat completed an internal investigation and determined that the XZ Utils vulnerability does not affect Neat products.

Impact

Not applicable to Neat products. For organizations directly running an affected version of XZ Utils, the vulnerability could allow a remote attacker to execute arbitrary code via the SSH authentication process.

Details

The backdoor is believed to have been deliberately introduced by one of the XZ Utils project maintainers. It is present only in a complete package download of versions 5.6.0 and 5.6.1, not in the standard Git source repository.

Remediation

No action is required for Neat products. Organizations running XZ Utils 5.6.0 or 5.6.1 directly should update per guidance from their Linux distribution.

Acknowledgements

Not applicable — identified and reported by the open-source security community.

References

Contact

Questions about this advisory can be directed to security@neat.no.